Security & Governance

AI agent security and governance.
Keep the work reviewable.

Evaluate the controls around people, agents, tools, and data. The platform provides specific access and review mechanisms; your deployment configuration determines which are enabled and how they operate.

Scoped access and credentials

Action-specific human review

Configurable evidence and retention

01 / Identity and access

Separate use from administration.

Organization roles distinguish identity, security, agent management, audit, and billing responsibilities. Team roles and agent collaborators provide more focused access to shared work.

01

Organization and Team boundaries

Control membership and workspace placement. Organization-private agents remain subject to company policy and authorized administration without automatically sharing their work with ordinary coworkers. Linking agents does not merge their access.

02

Enterprise sign-in and provisioning

SAML 2.0 and OpenID Connect SSO, SCIM provisioning, and group mappings are available subject to deployment enablement and setup. SSO requires domain verification, provider testing, and activation; it is not enabled in every deployment.

03

Sessions and offboarding

Configure session lifetimes, idle timeouts, and recent authentication for sensitive changes. Authorized administrators can inspect and revoke recorded access grants. API keys and background agents have separate access controls from interactive sessions.

02 / Credentials and system access

Grant the access the work needs.

Managed secrets use encrypted storage and dedicated input fields, separate from ordinary chat. Customers remain responsible for the permissions of the underlying accounts and services.

01

Scope credentials and destinations

Assign credentials at supported agent, workspace, Team, or Organization scopes. Use destination restrictions and explicit grants. Rotate or revoke underlying provider credentials as part of your access-management process.

02

Expose selected API operations

Supported OpenAPI specifications can become curated integrations. Administrators choose operations, credentials, and read, autonomous-write, or approval-required policies. Supported response fields can be redacted before results reach the agent.

03

Control machine access

Organization-managed client certificates can authorize mutual-TLS access to HTTPS services with destination, method, and path grants. Access to private destinations also requires operator network policy. TaskGlass computer access is separately paired and revocable.

03 / Human decisions

Make the review point explicit.

The platform enforces review for specific supported actions. An agent charter can describe expected behavior, but an instruction to ask permission is not a universal technical approval gate.

01

Review covered email before delivery

When enabled, Review Before Send holds covered external emails in an Outbox. Authorized reviewers inspect recipients, content, and attachments, edit supported content, and approve the saved version. Approval queues delivery; it does not establish receipt.

02

Approve a particular API call

Approval-required OpenAPI operations present the proposed arguments and execution context. Approval applies to that request; credential changes, revisions, or expiry can invalidate it. These controls do not automatically cover every browser or third-party write.

04 / Evidence and data handling

Know what was recorded—and what was not.

Work timelines and administrative activity help reviewers understand what happened. Audit coverage, evidence capture, exports, and retention depend on policy, permissions, and enabled features.

01

Administrative and agent evidence

The security ledger records covered administrative changes and supports CSV exports. Agent Audit View, where enabled, shows recorded runs, actions, outcomes, coverage indicators, and capture gaps. Full evidence must have been captured to be available for review.

02

Retention and exports

Configure supported retention for messages, files, and run history. Audit evidence has its own policy, and required operational and usage records may be retained. Cleanup does not remove copies at external providers or previously downloaded exports.

03

Files, execution, and network controls

Covered files stay unavailable until scanning clears them, subject to source policy and scanner configuration. Optional sandbox compute separates code execution from the application. Isolation and destination validation vary by execution path and must be reviewed in the deployment.

05 / Customer responsibilities

Turn controls into an operating practice.

Customers set information policy, authorize accounts and integrations, assign reviewers, and decide what work is appropriate. Platform operators configure the infrastructure and services that enforce the agreed boundaries.

01

Review the proposed environment

Assess identity setup, data flows, network paths, provider terms, evidence capture, and recovery with your security team. No certification, authorization, or blanket compliance status is asserted by these capability descriptions.

Review deployment dependencies
02

Validate representative work

Test permissions, failure cases, human decisions, and output quality before expanding use. DT can support that evaluation and the documentation, training, and implementation around it.

Explore evaluation and implementation

Use the AI technology evaluation scorecard to record how these controls meet your requirements, what evidence is available, and which questions need testing.

Next steps

What will your team build?

Explore the platform around your systems and workflows. Your team can lead implementation, with DT engineering or independent consulting available when you need it.